Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

RatHat Android Banking Trojan Operates via Malware‑as‑a‑Service Console, Targeting High‑Value Victims

Cleafy reports a new Android banking trojan, RatHat, offered as a service that uses a web console and a Gemini scoring engine to prioritize high‑value victims. The threat highlights the need for continuous mobile‑endpoint monitoring and audit‑ready evidence for financial‑services compliance.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
thehackernews.com

RatHat Android Banking Trojan Operates via Malware‑as‑a‑Service Console, Targeting High‑Value Victims

What Happened — Researchers at Cleafy identified a new Android banking trojan, RatHat, that is offered as a malware‑as‑a‑service. Operators control infected devices through a web‑based console that aggregates stolen data and uses a “Gemini” scoring engine to prioritize higher‑value victims. Nearly 100 distinct console deployments have been observed since April 2026.

Why It Matters for Trust & Control Assurance

  • The campaign demonstrates how a lack of continuous endpoint monitoring lets adversaries run a scalable “service” that harvests credentials at scale.
  • Defensible audit evidence (e.g., MDM logs, network traffic captures) is required to prove that mobile devices are protected and that suspicious data exfiltration is detected in real time.
  • Continuous control‑assurance programs that enforce strict mobile‑device policies and verify credential‑use can block the initial infection and provide the evidence needed for regulatory reviews.

Who Is Affected

  • Financial services firms that rely on mobile banking apps.
  • Enterprises with BYOD programs that allow Android devices on corporate networks.
  • Mobile‑app developers and SDK providers whose code may be repackaged by threat actors.

Recommended Actions

  • Enforce a robust Mobile Device Management (MDM) solution that enforces app‑allow lists, runtime integrity checks, and remote wipe capabilities.
  • Implement continuous monitoring of credential‑related API calls and anomalous data‑exfiltration patterns from mobile endpoints.
  • Conduct regular security‑awareness training focused on sideloaded apps and suspicious permissions.
  • Collect and retain forensic logs (device telemetry, network flows) to support audit readiness and incident response.

Technical Notes – The trojan is delivered via malicious APKs that request banking‑related permissions. Once installed, it captures keystrokes, SMS OTPs, and banking app screenshots, then uploads the data to the RatHat console. The Gemini engine scores victims based on account balances and transaction history, prioritizing those with higher monetary value. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →